FISMA
FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust

FISMA FISMA-3556-FederalCIRC-3557-NSS: Federal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557)

44 USC 3556 - Federal Information Security Incident Center (FedCIRC, now CISA US-CERT). The CISA Director operates the federal information security incident center providing: (a) timely warnings on emerging threats; (b) technical assistance to agencies in incident response; (c) consolidated central incident reporting + tracking; (d) coordination with private sector + sector ISACs + international partners; (e) information sharing under FISMA + CISA's Cybersecurity Information Sharing Act 2015 (CISA 2015) authorities. THE FEDERAL INCIDENT NOTIFICATION GUIDELINES require: (a) AGENCY HOTLINE notification within 1 HOUR for high-severity incidents (e.g. nation-state activity + significant data exfiltration + critical-infrastructure impact); (b) 4-HOUR notification for moderate-severity incidents; (c) WEEKLY status updates during open incidents; (d) FINAL REPORT within 30 days of closure. 44 USC 3557 - NATIONAL SECURITY SYSTEMS EXCLUSION. National security systems (NSS) are EXCLUDED from FISMA + governed separately by: (a) the Committee on National Security Systems (CNSS) under the National Security Agency; (b) CNSS Policies (CNSSP) + Instructions (CNSSI) including CNSSI 1253 (Security Categorization + Control Selection for NSS); (c) Intelligence Community Directive (ICD) 503 + the IC IT Enterprise (ICITE); (d) the Director of National Intelligence (DNI) + the Secretary of Defense + the Director of NSA. NSS includes classified systems + cryptographic systems + weapons systems + command and control + military command + intelligence activities. CRITICAL: agencies operating BOTH FISMA + NSS systems must clearly delineate the boundary + governance + handle controlled unclassified information (CUI) at the appropriate level.

Other controls in FISMA: National Security Systems Exclusion + CIRCIA + Zero Trust

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.